What Is NYDFS 23 NYCRR 500?

The New York Department of Financial Services Cybersecurity Regulation, known as 23 NYCRR Part 500, is one of the most prescriptive and aggressively enforced cybersecurity mandates in the United States. First enacted in 2017 and significantly amended in November 2023, it applies to every entity operating under a license, registration, or charter from the New York Banking Law, Insurance Law, or Financial Services Law — including banks, insurance companies, mortgage companies, money transmitters, and licensed lenders.

The 2023 amendments introduced personal accountability for senior leadership. Under Section 500.17(b), the annual compliance certification must now be co-signed by both the CEO and the CISO, creating direct personal liability for cybersecurity failures.

The Penetration Testing Requirement

Section 500.5 of the regulation requires every covered entity to conduct annual penetration testing of its information systems based on the entity's risk assessment. Specifically, the regulation requires:

  • Annual penetration testing of information systems
  • Bi-annual vulnerability assessments (at minimum)
  • Testing must be risk-based and cover systems identified in the entity's risk assessment
  • Results must be documented and retained for at least five years
  • Identified vulnerabilities must be remediated on a defined schedule

Class A Companies Face Additional Requirements

The 2023 amendment created a new category — "Class A Companies" — defined as entities with over $20 million in gross annual revenue in each of the last two fiscal years from New York operations, or over $1 billion in total gross annual revenue. Class A Companies face stricter requirements including mandatory independent audits, privileged access management (PAM) solutions, and endpoint detection and response (EDR) systems.

What NYDFS Examiners Look For

NYDFS has ramped up enforcement significantly since 2022, issuing consent orders and fines reaching into the tens of millions of dollars. During examinations, regulators typically request:

  • The most recent penetration test report — including scope, methodology, and findings
  • Evidence of remediation for critical and high findings
  • Documentation showing the test was conducted by a qualified firm
  • The risk assessment that informed the testing scope
  • Vulnerability assessment results and remediation tracking

What Grid32 Provides for NYDFS Compliance

Grid32 has conducted NYDFS-aligned penetration tests for financial institutions in New York since the regulation's inception. Our reports are structured to satisfy examiner requests directly: an executive summary suitable for board review, detailed technical findings with severity ratings and remediation guidance, evidence of methodology, and a client-facing attestation letter confirming scope and completion. We retain documentation that supports the five-year retention requirement.

Ready to satisfy your NYDFS requirement?

Grid32 has completed NYDFS-compliant penetration tests for financial institutions across New York since 2009. Our reports are built for examiners, not just engineers.

Get a Quote →